Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-dev-images.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build-dev-images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-dev-images.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build-dev-images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-dev-images.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build-dev-images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:201: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:202: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:214: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:143: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:161: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:163: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:189: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:190: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:114: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-links.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/check-links.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/check-links.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/check-links.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/close-stale.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/close-stale.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:147: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-mod-tidy.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/go-mod-tidy.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-mod-tidy.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/go-mod-tidy.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/golangci-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-lint.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/helm-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-lint.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/helm-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/openshift-preflight.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/openshift-preflight.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/openshift-preflight.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/openshift-preflight.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:138: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:142: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:150: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:163: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:221: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:233: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:238: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-odiglet-base-builder.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-odiglet-base-builder.yaml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-odiglet-base-builder.yaml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-odiglet-base-builder.yaml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-odiglet-base-builder.yaml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-odiglet-base-builder.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:137: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:147: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync-logos-s3-bucket.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/sync-logos-s3-bucket.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sync-logos-s3-bucket.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/sync-logos-s3-bucket.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tag-patch.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/tag-patch.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-otel-versions.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/update-otel-versions.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-otel-versions.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/update-otel-versions.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-api-crds.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-api-crds.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-api-crds.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-api-crds.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-collector-ocb.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-collector-ocb.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-collector-ocb.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-collector-ocb.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-odiglet-base-builder.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/verify-odiglet-base-builder.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/verify-odiglet-base-builder.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/verify-odiglet-base-builder.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-odiglet-base-builder.yaml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:30: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:b35229a3a6398fe8f86138c74c611e386f128c20378354fc5442811700d5600d
Warn: containerImage not pinned by hash: Dockerfile.rhel:1
Warn: containerImage not pinned by hash: Dockerfile.rhel:29: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-micro:latest to registry.access.redhat.com/ubi9/ubi-micro:latest@sha256:8a6071b01366611fd9433bf9688f5c3150de819874fa2c06c4fcd4c25ea26f03
Warn: containerImage not pinned by hash: collector/Dockerfile:1
Warn: containerImage not pinned by hash: collector/Dockerfile:8: pin your Docker image by updating gcr.io/distroless/base:latest to gcr.io/distroless/base:latest@sha256:125eb09bbd8e818da4f9eac0dfc373892ca75bec4630aa642d315ecf35c1afb7
Warn: containerImage not pinned by hash: collector/Dockerfile.rhel:1
Warn: containerImage not pinned by hash: collector/Dockerfile.rhel:9: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-micro:latest to registry.access.redhat.com/ubi9/ubi-micro:latest@sha256:8a6071b01366611fd9433bf9688f5c3150de819874fa2c06c4fcd4c25ea26f03
Warn: containerImage not pinned by hash: frontend/Dockerfile:1
Warn: containerImage not pinned by hash: frontend/Dockerfile:6
Warn: containerImage not pinned by hash: frontend/Dockerfile:12
Warn: containerImage not pinned by hash: frontend/Dockerfile:20: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:b35229a3a6398fe8f86138c74c611e386f128c20378354fc5442811700d5600d
Warn: containerImage not pinned by hash: frontend/Dockerfile.rhel:1
Warn: containerImage not pinned by hash: frontend/Dockerfile.rhel:6
Warn: containerImage not pinned by hash: frontend/Dockerfile.rhel:12
Warn: containerImage not pinned by hash: frontend/Dockerfile.rhel:21: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-micro:latest to registry.access.redhat.com/ubi9/ubi-micro:latest@sha256:8a6071b01366611fd9433bf9688f5c3150de819874fa2c06c4fcd4c25ea26f03
Warn: containerImage not pinned by hash: odiglet/Dockerfile:4
Warn: containerImage not pinned by hash: odiglet/Dockerfile:19
Warn: containerImage not pinned by hash: odiglet/Dockerfile:35
Warn: containerImage not pinned by hash: odiglet/Dockerfile:52
Warn: containerImage not pinned by hash: odiglet/Dockerfile:62
Warn: containerImage not pinned by hash: odiglet/Dockerfile:88
Warn: containerImage not pinned by hash: odiglet/Dockerfile:122: pin your Docker image by updating gcr.io/distroless/base:latest to gcr.io/distroless/base:latest@sha256:125eb09bbd8e818da4f9eac0dfc373892ca75bec4630aa642d315ecf35c1afb7
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:4
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:19
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:35
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:52
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:62
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:88
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:123: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-micro:latest to registry.access.redhat.com/ubi9/ubi-micro:latest@sha256:8a6071b01366611fd9433bf9688f5c3150de819874fa2c06c4fcd4c25ea26f03
Warn: containerImage not pinned by hash: odiglet/base.Dockerfile:1
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:3
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:18
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:34
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:51
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:61
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:87
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:124: pin your Docker image by updating registry.fedoraproject.org/fedora-minimal:38 to registry.fedoraproject.org/fedora-minimal:38@sha256:46d9dd1088e30a5ae8cf0f3907ce97c11f59d189fc2067d96264568945a2923e
Warn: containerImage not pinned by hash: operator/Dockerfile:2
Warn: containerImage not pinned by hash: operator/Dockerfile:28: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:b35229a3a6398fe8f86138c74c611e386f128c20378354fc5442811700d5600d
Warn: containerImage not pinned by hash: operator/Dockerfile.rhel:2
Warn: containerImage not pinned by hash: operator/Dockerfile.rhel:27: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-micro:latest to registry.access.redhat.com/ubi9/ubi-micro:latest@sha256:8a6071b01366611fd9433bf9688f5c3150de819874fa2c06c4fcd4c25ea26f03
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/cpp-http-server/Dockerfile:2
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/cpp-http-server/Dockerfile:23: pin your Docker image by updating alpine:latest to alpine:latest@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-glibc.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-glibc.Dockerfile:8: pin your Docker image by updating mcr.microsoft.com/dotnet/aspnet:6.0 to mcr.microsoft.com/dotnet/aspnet:6.0@sha256:e70c493f8af7f95bf459cb2b15c7e7a6173228929c2b7a9a6836b19377890e78
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-musl.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-musl.Dockerfile:8: pin your Docker image by updating mcr.microsoft.com/dotnet/aspnet:6.0-alpine to mcr.microsoft.com/dotnet/aspnet:6.0-alpine@sha256:02a9f6b3d99095659228667f3c88aecf4fe331935b7b861a6c17f130b3cd97a1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-glibc.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-glibc.Dockerfile:7: pin your Docker image by updating mcr.microsoft.com/dotnet/aspnet:8.0 to mcr.microsoft.com/dotnet/aspnet:8.0@sha256:3a305bc84767bbb651bd035119fe319a91fe927155706f7296499ca0205c812a
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-musl.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-musl.Dockerfile:7: pin your Docker image by updating mcr.microsoft.com/dotnet/aspnet:8.0-alpine to mcr.microsoft.com/dotnet/aspnet:8.0-alpine@sha256:0389d5b7d60f75ebbeec3bfffd2ad0a06d234e7b998231a5a86abf5e919a7d01
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-azul.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-azul.Dockerfile:6: pin your Docker image by updating azul/zulu-openjdk-alpine:17.0.12-jre-headless to azul/zulu-openjdk-alpine:17.0.12-jre-headless@sha256:12e335ed6d5cb4cd55ef6b5e2e769b2a77f25ced0270df1277bc2bca3dfd209e
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-latest-version.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-latest-version.Dockerfile:6: pin your Docker image by updating eclipse-temurin:latest to eclipse-temurin:latest@sha256:6634936b2e8d90ee16eeb94420d71cd5e36ca677a4cf795a9ee1ee6e94379988
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-old-version.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-old-version.Dockerfile:6: pin your Docker image by updating eclipse-temurin:11-jre-jammy to eclipse-temurin:11-jre-jammy@sha256:edbb5097b308aaae292b6f74b5e6bfac223185a9f3d23380839c4c555fab003b
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-docker-env.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-docker-env.Dockerfile:6: pin your Docker image by updating eclipse-temurin:17.0.12_7-jre-jammy to eclipse-temurin:17.0.12_7-jre-jammy@sha256:6c4c0938462c9678fe380bf01c7da7f4242dc20f54362f24ced3bb70f6e0183a
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-manifest-env.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-manifest-env.Dockerfile:6: pin your Docker image by updating eclipse-temurin:17.0.12_7-jre-jammy to eclipse-temurin:17.0.12_7-jre-jammy@sha256:6c4c0938462c9678fe380bf01c7da7f4242dc20f54362f24ced3bb70f6e0183a
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-version.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-version.Dockerfile:6: pin your Docker image by updating eclipse-temurin:17.0.12_7-jre-jammy to eclipse-temurin:17.0.12_7-jre-jammy@sha256:6c4c0938462c9678fe380bf01c7da7f4242dc20f54362f24ced3bb70f6e0183a
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/dockerfile-env.Dockerfile:1: pin your Docker image by updating node:20.17.0-alpine to node:20.17.0-alpine@sha256:2d07db07a2df6830718ae2a47db6fedce6745f5bcd174c398f2acdda90a11c03
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/latest-version.Dockerfile:1: pin your Docker image by updating node:current-alpine to node:current-alpine@sha256:6eae672406a2bc8ed93eab6f9f76a02eb247e06ba82b2f5032c0a4ae07e825ba
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/manifest-env.Dockerfile:1: pin your Docker image by updating node:20.17.0-alpine to node:20.17.0-alpine@sha256:2d07db07a2df6830718ae2a47db6fedce6745f5bcd174c398f2acdda90a11c03
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/minimum-version.Dockerfile:1: pin your Docker image by updating node:14.0.0-alpine to node:14.0.0-alpine@sha256:628ae0898c092799f09af3f15775b9d5f2feeafc1bb2485e68d577f3ea8f267e
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/unsupported-version.Dockerfile:1: pin your Docker image by updating node:8.17.0-alpine to node:8.17.0-alpine@sha256:38f7bf07ffd72ac612ec8c829cb20ad416518dbb679768d7733c93175453f4d4
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/very-old-version.Dockerfile:1: pin your Docker image by updating node:8.17.0-alpine to node:8.17.0-alpine@sha256:38f7bf07ffd72ac612ec8c829cb20ad416518dbb679768d7733c93175453f4d4
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-alpine:2: pin your Docker image by updating python:3.10.15-alpine to python:3.10.15-alpine@sha256:039508c234f83314a3be8eed523f347f6f26816541be7caa4a9ef4a4bf1bfb66
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-latest:1: pin your Docker image by updating python to python@sha256:8c55c44b9e81d537f8404d0000b7331863d134db87c1385dd0ec7fefff656495
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-min-version:2: pin your Docker image by updating python:3.8.0-slim to python:3.8.0-slim@sha256:8e243f41e500238f78f7a29a81656114d3fe603d5c34079a462d090f71c4b225
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-not-supported-version:2: pin your Docker image by updating python:3.6-slim to python:3.6-slim@sha256:2cfebc27956e6a55f78606864d91fe527696f9e32a724e6f9702b5f9602d0474
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-other-agent:1: pin your Docker image by updating python to python@sha256:8c55c44b9e81d537f8404d0000b7331863d134db87c1385dd0ec7fefff656495
Warn: pipCommand not pinned by hash: odiglet/Dockerfile:8
Warn: pipCommand not pinned by hash: odiglet/Dockerfile.rhel:8
Warn: pipCommand not pinned by hash: odiglet/debug.Dockerfile:7
Warn: goCommand not pinned by hash: odiglet/debug.Dockerfile:106
Warn: nugetCommand not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-glibc.Dockerfile:5: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-musl.Dockerfile:5: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-glibc.Dockerfile:4: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-musl.Dockerfile:4: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-alpine:5
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-alpine:10
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-latest:11
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-min-version:14
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-not-supported-version:8
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-other-agent:11
Warn: pipCommand not pinned by hash: .github/workflows/generated-docs.yaml:53
Warn: pipCommand not pinned by hash: .github/workflows/generated-docs.yaml:54
Warn: pipCommand not pinned by hash: .github/workflows/generated-docs.yaml:78
Warn: pipCommand not pinned by hash: .github/workflows/generated-docs.yaml:79
Info: 0 out of 64 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 47 third-party GitHubAction dependencies pinned
Info: 0 out of 13 pipCommand dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned
Info: 0 out of 4 nugetCommand dependencies pinned
Info: 0 out of 75 containerImage dependencies pinned